SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Aiven is a global team of over 400 people building a cloud data platform that makes open-source databases, search, streaming, and application infrastructure accessible to everyone. You'll join the Security & Compliance team as a Senior IAM Engineer, owning identity and access management end-to-end across the organization.
In this role, you'll be the reference point for identity and access across Aiven. Identity is the control plane for the company—every employee, service, and automation reaches systems through it. You'll own the complete joiner-mover-leaver lifecycle flowing from the HRIS system through Okta to downstream applications, manage access request and review processes that keep entitlements defensible, and build automation that sustains both without manual intervention.
You'll work at the center of a cross-functional web, partnering closely with Engineering, IT, People Operations, and Security Operations. Day-to-day, you'll live in Okta as your core platform, orchestrating lifecycle automation through Okta Workflows, managing access requests and approvals via Jira, and integrating identity across enterprise SaaS tools, major cloud providers (AWS, GCP, Azure), and internal systems.
Key responsibilities include:
- Own employee lifecycle end-to-end, from HRIS through Okta to downstream applications
- Build and maintain automation in Okta Workflows, driven by HRIS as source of truth
- Extend IAM practices to non-human identities: define provisioning, scoping, review, and deprovisioning for service accounts, bots, and AI agents
- Own access request and approval processes, keeping routine access efficient and sensitive access controlled and auditable
- Build self-service access capabilities and define/maintain per-role access policies
- Onboard new applications to SSO and automated provisioning; design role-based access including Okta group structure, application role mappings, SCIM provisioning
- Review new integrations and access requests, assessing permission scope and credential exposure
- Provide identity evidence for PCI, SOC 2, and ISO 27001 compliance
The role carries genuine technical breadth and suits an engineer who treats recurring manual work as a defect to be resolved through AI systems or repeatable automation.
REQUIREMENTS:
- Five or more years in IAM, identity engineering, or closely related security discipline, with demonstrable ownership of an identity platform (not just operational support)
- Deep IdP expertise; Okta experience strongly preferred (other platforms like Entra ID/Ping considered)
- Proficiency in automation using Python, JavaScript, or similar languages to support automation of routine identity tasks
- Fluent with AI tooling and able to understand how to utilize and leverage AI to enhance IAM capabilities and service delivery
- Experience owning technical employee onboarding and offboarding end-to-end, including managing access requests and approvals, and automating fulfillment through Okta
- Hands-on cloud IAM experience with at least one major cloud provider (AWS, GCP, or Azure), including roles, policies, permission boundaries, and identity federation
- Experience with Infrastructure as Code for identity resources (e.g., Terraform) so access configuration is version-controlled and reviewable
- Comfort with ambiguity and strong sense of ownership; ability to define and own undefined work
NICE TO HAVE:
- Deep, practical Okta expertise across Universal Directory, profile mappings and sourcing, group rules and Expression Language, application assignments, SSO, and lifecycle management
- Demonstrated experience automating identity processes with Okta Workflows or equivalent platform, driven by HRIS as source of truth
- Broader security knowledge beyond identity (e.g., security operations, vulnerability management, cloud security posture, incident response)
- Experience governing machine identities, including service accounts, API tokens, bot users, and credentials for automation platforms or AI agents
- Exposure to IGA products, GRC platforms, or access certification tooling